Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Mar 2026Messina Social CityMessina Social City was fined by the Garante 10,000 EUR for breaching GDPR principles. The case concerned the improper dissemination of personal data, including images of minors, on Facebook without proper legal grounds and contracts.ITGaranteGDPR€10,000
26 Mar 2026Provvedimento del 26 marzo 2026 [10241477]A doctor did not comply with a request to delete data and provided patients with incomplete information, which constituted a breach of GDPR Article 13. The Garante imposed a fine of EUR 2,000.ITGaranteGDPR€2,000
26 Mar 2026Comune di XXThe Garante fined Comune di XX EUR 5,000 for breaches of lawfulness, fairness, transparency, and data minimization. It also found failures to implement data protection by design and by default.ITGaranteGDPR€5,000
26 Mar 2026Eni S.p.A.Eni S.p.A. was fined 96,000 EUR by the Garante for publishing personal data on its website, including dates of birth and addresses, without proper masking. The authority found this breached GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€96,000
26 Mar 2026SOCIÉTÉ AYANT POUR ACTIVITÉ L'HÉBERGEMENT DE TOURISME (procédure simplifiée)CNIL imposed an administrative fine of EUR 3,000 on SOCIÉTÉ AYANT POUR ACTIVITÉ L'HÉBERGEMENT DE TOURISME under a simplified procedure. The case concerns a confirmed breach of rules supervised by CNIL.FRCNILGDPR€3,000
26 Mar 2026PSK AD Network S.r.l.PSK AD Network S.r.l. was fined EUR 5,000 by the Garante. The case concerned the failure to respond to a data subject’s deletion request and the failure to provide information requested by the authority, in breach of Article 157 of the Codice.ITGaranteGDPR€5,000
26 Mar 2026SOCIÉTÉ ORGANISANT DES ÉVÈNEMENTS PAR LA PROMOTION ET LA VENTE DE BILLETS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on the company organizing events and selling tickets, and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€15,000
26 Mar 2026Ordine degli Avvocati di PiacenzaOrdine degli Avvocati di Piacenza was fined EUR 3,000 by the Garante for improper handling of disciplinary sanctions in its professional register. The authority found that the processing did not comply with data protection requirements.ITGaranteGDPR€3,000
26 Mar 2026Comune di CassinoComune di Cassino was fined for unlawfully publishing personal data online. The case concerns a breach of data protection rules and indicates a need to review procedures for publishing public information.ITGaranteGDPR€2,500
26 Mar 2026Comune di XXThe Garante fined Comune di XX EUR 3,000 for breaches of GDPR Articles 6 and 9 and Article 2-ter of the Italian Privacy Code. The case concerned processing personal data without a proper legal basis.ITGaranteGDPR€3,000
30 Mar 2026Energy Prices Direct LimitedThe ICO fined Energy Prices Direct Limited, an energy switching services provider, for breaches of the PECR. The company obtained data from public sources and list providers, but failed to screen it against the TPS/CTPS registers before making marketing calls.GBICOePrivacy€184,000
30 Mar 2026Κέντρο Εκπαίδευσης και Αποκατάστασης Τυφλών (ΚΕΑΤ)The Greek Data Protection Authority fined ΚΕΑΤ EUR 5,000 for an untimely and improper response to an employee’s request for access to CCTV footage. The case involved edited footage, missing material, and inadequate technical and organizational measures to support compliance.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€5,000
02 Apr 2026SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES (procédure simplifiée)CNIL imposed an administrative fine of EUR 7,500 on SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES under a simplified procedure. The case concerns a breach of rules covered by the authority’s decision.FRCNILGDPR€7,500
03 Apr 2026BLUE PROJECTS S.R.L.In March 2026, the Romanian supervisory authority ANSPDCP completed an investigation into BLUE PROJECTS S.R.L. and found a GDPR violation. The company was fined EUR 2,500.ROANSPDCPGDPR€2,500
07 Apr 2026Dane anonimowe (Wspólnotę Mieszkaniową K.)The UODO imposed an administrative fine on K. Housing Community for failing to report a personal data breach without undue delay, and no later than 72 hours after becoming aware of it. The case concerns the obligation to notify the President of the UODO within the statutory deadline.PLUODOGDPR€1,135
13 Apr 2026Dane anonimowe (Pana L. A. prowadzącego działalność gospodarczą pod nazwą: A.)UODO issued a reprimand to the controller, two agents and a sub-agent, and imposed an administrative fine on the sub-agent. The case concerned GDPR breaches related to processing security, verification of processors, and the principles of confidentiality and accountability.PLUODOGDPR€2,385
15 Apr 2026Javno komunalno podjetjeThe Slovenian Information Commissioner fined a municipal utility company EUR 6,000 for continuously and indiscriminately collecting employees’ location data via GPS trackers in company vehicles. The authority found no valid legal basis under GDPR Article 6 and also noted inadequate employee notice and a failure to assess legitimate interest separately for each processing purpose.SIInformacijski pooblaščenecGDPR€6,000
16 Apr 2026An unnamed energy companyHungary’s data protection authority, NAIH, imposed a HUF 75 million GDPR fine in case NAIH-19-18/2024 on an unnamed energy company. The case concerned data processing for a nationwide LED replacement program and identified serious privacy compliance failures.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€205,000
17 Apr 2026Comune di Campo CalabroThe Garante fined Comune di Campo Calabro EUR 6,000 for publishing personal data online. The case concerned a breach of data protection rules and the unlawful disclosure of information.ITGaranteGDPR€6,000
17 Apr 2026Framos Italia s.r.l. in liquidazioneFramos Italia s.r.l. in liquidation was fined EUR 5,000 by the Garante. The authority found that former employees’ email accounts were not deactivated and that information on data processing was not clear and comprehensive.ITGaranteGDPR€5,000